Cryptoramic

Terminology

What is CADI? Cryptographic asset discovery and inventory explained

The category has several names. The job is the same, and it starts before post-quantum migration and outlives it.

The panoramic view: sources, inventory, context and decisions Five kinds of sources feed one inventory in which every finding keeps its source. Policy, software and supplier context and ownership are attached to it, and the result is a set of decisions: fix, migrate, ask the supplier, verify. Sources you already control Files and keystores Containers, images Network services Traffic captures Repositories Inventory every finding keeps its source Context, added as it arrives Policy and regulation Software and suppliers Ownership, from your CMDB Decisions fix locally · migrate · ask the supplier · rescan to verify Context enriches the picture.Not a precondition for a first result.
  1. Discover

    Bring files, images, network observations and software evidence into one inventory.

  2. Connect

    Keep the source of each finding and add policy, ownership and supplier context.

  3. Act

    Prioritize findings, review report views and agree the next change with its owner.

The panoramic view: sources feed one inventory, context is added as it arrives, decisions come out.

What does CADI mean?

CADI stands for cryptographic asset discovery and inventory. It is the practice, and the category of tools, for finding the cryptography an organization depends on and recording it in a form that supports decisions: which certificates, keys, algorithms and protocols exist, where they were observed, what software and services use them, and how that compares with policy.

The term is used in procurement and in government guidance, including a 2025 market survey of CADI tooling that TNO carried out for the Dutch government (our summary), because a cryptographic inventory is the precondition for almost every other cryptographic control: certificate lifecycle management, crypto-agility, post-quantum migration and audit evidence all start from knowing what is there.

How does CADI differ from a certificate inventory?

A certificate inventory records certificates and their properties, usually from a certificate authority, a load balancer or a network scan. CADI is broader on three axes:

A certificate inventory is a useful part of a cryptographic inventory. It is not a substitute for it.

An asset's relationship graph in Cryptoramic: signed-by, depends-on, located-at and found-in relationships with the host, scan and related certificates.
Asset relationships · Illustrative assessment data

What is a CBOM, and how does it relate?

A cryptographic bill of materials (CBOM) is a structured document, standardized in CycloneDX, that lists the cryptographic assets and dependencies of a system or product. CADI produces the observations; a CBOM is one way to exchange them, for example with a supplier, an auditor or a software supply-chain process. A CADI tool should import CBOMs it receives and export CBOMs for the scope it has assessed.

Where do crypto-agility and cryptographic posture management fit?

Crypto-agility is the ability to change algorithms, keys and protocols without redesigning systems. Cryptographic posture management (CPM) is the continuous assessment of an estate against cryptographic policy. Both depend on an inventory that is current and traceable. In practice the terms overlap: a CADI tool with policy evaluation and repeat assessments provides the posture view; the migration work that follows is where agility is tested.

Why does post-quantum migration make CADI urgent?

Post-quantum cryptography replaces the key-establishment and signature algorithms most systems use today. Migrating requires knowing where those algorithms are used, which software versions can be upgraded, which suppliers must deliver a change, and which data is exposed to a harvest-now-decrypt-later attack in the meantime. An inventory that stops at certificates misses most of that.

What should you look for in a CADI tool?

  1. Breadth of sources with provenance. Files, images, repositories, stores and traffic, with the discovery path kept for every finding.
  2. Policy assessment that explains itself. Findings tied to a rule, a source reference and a date, not a single opaque score.
  3. Software and supplier context. Product and version identification, so a finding turns into an upgrade or a supplier question.
  4. A deployment model your security team accepts. Runs on your infrastructure, keeps secret key material out of results, and works offline where needed.
  5. A first result without a platform project. You should be able to assess one golden image or one segment this week.

Cryptoramic is a CADI product with policy assessment, supplier readiness and reporting built in. Explore the platform or read what discovery covers.

Frequently asked questions

What does CADI stand for?

Cryptographic Asset Discovery and Inventory. It means finding the certificates, keys, algorithms and protocols your organization depends on, and recording where they are found and how they are used.

Is a CADI tool the same as a certificate manager?

No. Certificate management focuses on issuing, renewing and managing certificates. CADI looks more broadly for cryptography, including keys, software libraries and security settings. Some products combine these functions, so check their actual coverage.

What is the difference between a CBOM and a cryptographic inventory?

The inventory is your record of discovered cryptography. A cryptographic bill of materials, or CBOM, is a document describing cryptography for a particular system or product. You can export it to share findings with suppliers or auditors.

Do you need a complete cryptographic inventory before starting post-quantum migration?

No. Start with one application, network segment or set of software images. Fix the issues you can control and ask suppliers about the rest. Expand the inventory as you learn.

Back to perspectives

See what discovery finds in one representative scope.

Book a demo

Product screenshot

Illustrative assessment data